| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-67184 🧪 | TinyWeb 0.0.8 Null Pointer Dereference DoS via Malformed HTTP Request | GeneralSandman | TinyWeb | High | 7.5 | 2026-07-28 16:28:48 | Deep Dive |
| CVE-2026-54605 🧪 | OAuth: Cross-origin token-request redirects can expose signed request metadata | ruby-oauth | oauth | High | 7.2 | 2026-07-28 16:26:28 | Deep Dive |
| CVE-2026-67183 🧪 | TinyWeb 0.0.8 Memory Leak DoS via HTTP Request Handling | GeneralSandman | TinyWeb | High | 7.5 | 2026-07-28 16:26:09 | Deep Dive |
| CVE-2026-67182 🧪 | Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Header Injection | tomaka | rouille | High | 7.5 | 2026-07-28 16:18:09 | Deep Dive |
| CVE-2026-67181 🧪 | Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Transfer-Encoding Header | tomaka | rouille | Medium | 5.4 | 2026-07-28 16:10:30 | Deep Dive |
| CVE-2026-66754 🧪 | Rouille 0.1.6 - 3.6.2 Reachable Assertion DoS via remove_prefix percent-encoding | tomaka | rouille | Medium | 5.9 | 2026-07-28 16:04:30 | Deep Dive |
| CVE-2026-47483 🧪 | NVIDIA DCGM 资源管理错误漏洞 | NVIDIA | DCGM | High | 8.2 | 2026-07-28 15:55:31 | Deep Dive |
| CVE-2026-61609 🧪 | Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS) | pterodactyl | panel | High | 7.5 | 2026-07-28 15:45:58 | Deep Dive |
| CVE-2026-66752 🧪 | tiny-http 0.12.0 HTTP Request Smuggling via Transfer-Encoding Handling | tiny-http | tiny-http | Medium | 5.4 | 2026-07-28 15:44:42 | Deep Dive |
| CVE-2026-54593 🧪 | Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions | pterodactyl | panel | High | 8.1 | 2026-07-28 15:42:57 | Deep Dive |
| CVE-2026-43910 🧪 | Appium java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor | appium | java-client | High | 8.2 | 2026-07-28 15:38:24 | Deep Dive |
| CVE-2026-45293 🧪 | WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability | WordPress | WordPress-Coding-Standards | High | 8.6 | 2026-07-28 15:34:45 | Deep Dive |
| CVE-2026-47427 🧪 | GitHub MCP Server: Nil Pointer Dereference DoS in completion/complete Handler | github | github-mcp-server | High | 7.5 | 2026-07-28 15:32:27 | Deep Dive |
| CVE-2026-66748 🧪 | Camaleon CMS 2.1.1 - 2.9.1 Authenticated RCE via select_eval Custom Field | owen2345 | camaleon-cms | High | 8.8 | 2026-07-28 15:19:53 | Deep Dive |
| CVE-2026-54545 🧪 | @wakaru/cli arbitrary file write during bundle unpack | pionxzh | wakaru | High | 7.1 | 2026-07-28 14:43:46 | Deep Dive |
| CVE-2026-67178 🧪 | Open Redirect in MISP Installer-Generated Apache Configuration | misp | misp | High | 7.8 | 2026-07-28 14:30:22 | Deep Dive |
| CVE-2026-67174 🧪 | DOM-Based Cross-Site Scripting via Unsafe String and SVG Icon Rendering in Pivotick | pivotick | pivotick | Critical | 9.2 | 2026-07-28 13:53:42 | Deep Dive |
| CVE-2026-66920 🧪 | Pivotick - Stack Exhaustion Denial of Service via Deep or Cyclic Graph Data | Pivotick | Pivotick | High | 8.2 | 2026-07-28 12:57:21 | Deep Dive |
| CVE-2026-66918 🧪 | DOM-Based Cross-Site Scripting via Unsanitized SVG Node Icons | pivotick | pivotick | High | 8.2 | 2026-07-28 12:42:11 | Deep Dive |
| CVE-2026-65880 🧪 | Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 | balbooa.com | Balbooa Forms component for Joomla | Critical | 10.0 | 2026-07-28 10:27:16 | Deep Dive |